50. rke2 和 k3s “证书检查”命令在 2025 年 5 月发布之前,不会检查 Rancher 集群 kube-controller-manager 和 kube-scheduler 证书
- Rancher v2.7+ 牧场主 v2.7+
- A Rancher-provisioned RKE2 cluster < v1.30.13+rke2r1, v1.31.9+rke2r1, v1.32.5+rke2r1, or v1.33.1+rke2r1; or a Rancher-provisioned K3s cluster < v1.30.13+k3s1, v1.31.9+k3s1, v1.32.5+k3s1, or v1.33.1+k3s1
Rancher 配置的 RKE2 集群< v1.30.13+rke2r1、v1.31.9+rke2r1、v1.32.5+rke2r1 或 v1.33.1+rke2r1;或 Rancher 配置的 K3s 集群 <v1.30.13+k3s1、v1.31.9+k3s1、v1.32.5+k3s1 或 v1.33.1+k3s1
When the `rke2 certificate check` or `k3s certificate check` command is run on a server node in a Rancher-provisioned cluster, for an RKE2 or K3s version released prior to May 2025, output is missing for both the kube-controller-manager and kube-scheduler certificates, when compared with the output for a standalone cluster:
当在 Rancher 配置集群的服务器节点上运行“rke2 证书检查”或“k3s 证书检查”命令时,对于 2025 年 5 月之前发布的 RKE2 或 K3s 版本,kube 控制器管理器和 kube 调度器证书的输出都缺失,而独立集群的输出则不同:
<span style="color:#000000"><span style="background-color:#ffffff"><span style="background-color:#efefef"><code>$ rke2 certificate check
INFO[0000] Server detected, checking agent and server certificates
INFO[0000] Checking certificates for kube-proxy
INFO[0000] /var/lib/rancher/rke2/server/tls/client-kube-proxy.crt: certificate CN=system:kube-proxy is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/client-kube-proxy.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/agent/client-kube-proxy.crt: certificate CN=system:kube-proxy is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/agent/client-kube-proxy.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] Checking certificates for kubelet
INFO[0000] /var/lib/rancher/rke2/agent/client-kubelet.crt: certificate CN=system:node:test-rancheragent-rke2-all-0,O=system:nodes is ok, expires at 2026-02-07T09:50:10Z
INFO[0000] /var/lib/rancher/rke2/agent/client-kubelet.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/agent/serving-kubelet.crt: certificate CN=test-rancheragent-rke2-all-0 is ok, expires at 2026-02-07T09:50:09Z
INFO[0000] /var/lib/rancher/rke2/agent/serving-kubelet.crt: certificate CN=rke2-server-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] Checking certificates for rke2-controller
INFO[0000] /var/lib/rancher/rke2/server/tls/client-rke2-controller.crt: certificate CN=system:rke2-controller is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/client-rke2-controller.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/agent/client-rke2-controller.crt: certificate CN=system:rke2-controller is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/agent/client-rke2-controller.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] Checking certificates for api-server
INFO[0000] /var/lib/rancher/rke2/server/tls/client-kube-apiserver.crt: certificate CN=system:apiserver,O=system:masters is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/client-kube-apiserver.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/serving-kube-apiserver.crt: certificate CN=kube-apiserver is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/serving-kube-apiserver.crt: certificate CN=rke2-server-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] Checking certificates for cloud-controller
INFO[0000] /var/lib/rancher/rke2/server/tls/client-rke2-cloud-controller.crt: certificate CN=rke2-cloud-controller-manager is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/client-rke2-cloud-controller.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] Checking certificates for scheduler
INFO[0000] /var/lib/rancher/rke2/server/tls/client-scheduler.crt: certificate CN=system:kube-scheduler is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/client-scheduler.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] Checking certificates for supervisor
INFO[0000] /var/lib/rancher/rke2/server/tls/client-supervisor.crt: certificate CN=system:rke2-supervisor,O=system:masters is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/client-supervisor.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] Checking certificates for admin
INFO[0000] /var/lib/rancher/rke2/server/tls/client-admin.crt: certificate CN=system:admin,O=system:masters is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/client-admin.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] Checking certificates for auth-proxy
INFO[0000] /var/lib/rancher/rke2/server/tls/client-auth-proxy.crt: certificate CN=system:auth-proxy is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/client-auth-proxy.crt: certificate CN=rke2-request-header-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] Checking certificates for controller-manager
INFO[0000] /var/lib/rancher/rke2/server/tls/client-controller.crt: certificate CN=system:kube-controller-manager is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/client-controller.crt: certificate CN=rke2-client-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] Checking certificates for etcd
INFO[0000] /var/lib/rancher/rke2/server/tls/etcd/client.crt: certificate CN=etcd-client is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/etcd/client.crt: certificate CN=etcd-server-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/etcd/server-client.crt: certificate CN=etcd-server is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/etcd/server-client.crt: certificate CN=etcd-server-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/etcd/peer-server-client.crt: certificate CN=etcd-peer is ok, expires at 2026-02-07T09:41:47Z
INFO[0000] /var/lib/rancher/rke2/server/tls/etcd/peer-server-client.crt: certificate CN=etcd-peer-ca@1738921307 is ok, expires at 2035-02-05T09:41:47Z</code></span></span></span>
Upgrade the RKE2 or K3s cluster to a May 2025 release or later, per the versions in the Environment section above.
根据上文环境部分的版本,将 RKE2 或 K3s 集群升级到 2025 年 5 月或更晚版本。
In earlier RKE2 and K3s releases, per the versions in the Environment section, the certificates for the kube-scheduler and kube-controller-manager components were not generated by the RKE2/K3s supervisor process, but were auto-generated by the components themselves. In Rancher-provisioned clusters, these certificates were generated in component-specific subdirectories within the rke2 server tls directory, per the --cert-dir argument passed to the kube-scheduler and kube-controller-manager. These directories were not included in the checks performed by the `rke2 certificate check` and `k3s certificate check` commands. This behaviour was changed in the May 2025 releases. In these releases and later, the RKE2/supervisor process generates the kube-scheduler and kube-controller-manager certificates within these subdirectories, and they are included in the certificate check commands.
在早期的 RKE2 和 K3s 版本中,根据环境部分的版本,kube-scheduler 和 kube-controller-manager 组件的证书并非由 RKE2/K3s 的主管进程生成,而是由组件本身自动生成。在 Rancher 配置的集群中,这些证书根据传递给 kube 调度器和 kube-controller-manager 的--cert-dir 参数,在 rke2 服务器 TLS 目录内的组件特定子目录中生成。这些目录未包含在“rke2 certificate check”和“k3s certificate check”命令执行的检查中。这一行为在 2025 年 5 月版本中有所改变。在这些版本及以后版本中,RKE2/supervisor 进程在这些子目录内生成 kube 调度器和 kube-controller-manager 证书,并包含在证书检查命令中。
访问Rancher-K8S解决方案博主 :https://blog.csdn.net/lidw2009
更多推荐




所有评论(0)